|
|
| |
|
| |
nrpe: code execution
| Package(s): | NRPE |
CVE #(s): | CVE-2013-1362
|
| Created: | April 4, 2013 |
Updated: | April 5, 2013 |
| Description: |
From the openSUSE advisory:
NRPE (the Nagios Remote Plug-In Executor) allows the
passing of $() to plugins/scripts which, if run under bash,
will execute that shell command under a subprocess and pass
the output as a parameter to the called script. Using this,
it is possible to get called scripts, such as check_http,
to execute arbitrary commands under the uid that
NRPE/nagios is running as (typically, 'nagios').
With this update NRPE will deny remote requests containing
a bash command substitution.
|
| Alerts: |
|
( Log in to post comments)
|
|
|